Updated 1 October 2026.
Fuzer Ltd, trading as Fuzer, operates fuzer.co, Fuzer Connect, Entry Manager and related services. We are registered in England and Wales under company number 17060392, with our registered office at 167 - 169 Great Portland Street, 5th Floor, London, England, W1W 5PF.
For privacy questions, rights requests or complaints, email contact@fuzer.co or write to that address, marked "Privacy". You do not need to use legal language or a special form.
This Policy describes personal information relating to website visitors, account holders, buyers, attendees, resellers, people appearing in public profiles, and people who operate or work with event organisations. It covers collection through the Platform, communications and relevant information supplied by others. Applicable protection includes the UK GDPR and Data Protection Act 2018 as amended, the EU GDPR where applicable, Swiss data-protection law and applicable US privacy laws.
Fuzer is a controller where we decide why and how to use information, including operating accounts, arranging transactions, protecting the Platform, maintaining discovery and complying with law. Event sellers and other organisations may be separate controllers for running their events, admission, their customer relationships and their own marketing. They must provide their own privacy information. Where we handle an organisation's customer notes, campaigns or other records solely on its instructions, we act as its processor under the data-processing provisions in our Terms of Service. The actual purpose determines our role; an organisation does not own your personal information merely because you attended its event.
This Policy explains processing; it does not ask you to waive rights. Accepting the Terms, using the Platform or reading this Policy does not by itself provide consent to every use of your data.
We collect the following information to the extent relevant to the features you use:
Information also comes from the person booking on your behalf, event staff, business collaborators, service providers and authorities where lawfully supplied. If you supply information about someone else, give them appropriate notice and have authority and a lawful basis to do so.
Fields needed for an account, purchase, admission, payout or legally required verification are required for that purpose. Without them, we may be unable to provide the relevant service or release a payment. Optional interests, marketing permission and device location are not required simply to browse ordinary event listings; entering an area manually is an alternative to sharing device location.
Where UK or EU data-protection law requires a legal basis, we use the following purpose-specific bases. A reference to legitimate interests means we assess the purpose, necessity and impact on your rights, rather than treating our commercial interest as unrestricted permission.
We use account and transaction information to authenticate you, manage reservations, confirm bookings, deliver tickets, process resale, administer credits and payouts, provide support and send necessary service messages. We use contract necessity where this is necessary to perform our agreement with you or take steps you request before entering it. Where you are an attendee or an organisation's representative rather than our contracting customer, the basis is generally our and the relevant customer's legitimate interests in fulfilling the requested service, subject to your rights. Statutory financial or tax records rely on legal obligation where applicable.
We use business identity, access, agreement, promotion and operational records to administer Connect, verify authority, allocate agreed revenue, manage staff and provide permitted reports. The basis is contract necessity for a contracting individual and otherwise legitimate interests in delivering and safeguarding the organisation's service. Verification or reporting legally required of us relies on legal obligation. Processing solely on an organisation's instructions is governed by that controller's purposes and legal basis.
We use necessary account, technical, transaction and verification information to prevent bots, duplicate admissions, stolen payments, fraudulent events, abusive referrals and other misuse; investigate reports; resolve disputes; recover debts; and protect funds. The basis is legitimate interests in protecting users, Fuzer and payment systems, or legal obligation where a specific duty, sanctions requirement or binding order applies. Routine fraud prevention is not described as a legal obligation merely because it is useful. Establishing or defending claims may rely on legitimate interests and any separately required condition for sensitive information.
We use public event information, search requests and filters to provide discovery. We use optional interests and eligible account activity for recommendations, based on legitimate interests in providing relevant results with user controls, and consent where applicable law requires it, including for relevant storage or tracking. The same distinction applies to service measurement: proportionate operational statistics may rely on legitimate interests; optional analytics technologies require consent unless a valid legal exemption applies. We may create aggregate statistics that no longer identify individuals. Pseudonymous or small-group data remains protected personal information.
We use contact details and relevant preferences for marketing only with consent, or a specific alternative permitted by applicable marketing law, such as a properly implemented existing-customer exception. Where an exception applies, the associated data-processing basis is generally legitimate interests and there must still be a clear opt-out. We do not treat a purchase, a follow or the Terms as blanket permission for marketing from every event participant.
We use public professional information to maintain accurate event and performer listings and handle profile claims on the basis of legitimate interests, subject to objections, accuracy checks and the rights of the people concerned. We use necessary records for accounting, legal notices and mandatory disclosures on the basis of legal obligation. Handling claims, professional advice, business planning and a prospective business transfer generally relies on legitimate interests, with access limited to what is necessary and appropriate safeguards.
If a new purpose is incompatible with the purpose for which information was collected, we need an appropriate new basis and must provide any required further notice or consent request. The Terms do not supply permission for unrelated purposes.
Personalised discovery uses the interests you choose, profiles you follow and eligible recent activity and purchases to rank events. Location, date and other filters constrain results. Some suggestions introduce variety. The result is a different event order or selection, not a guarantee that an event suits you or an assessment of your eligibility for credit.
When you submit a natural-language interests description, we send that description to OpenAI through its API to extract event preferences, such as categories, performers and expressed dislikes. The request uses the description rather than your payment details or full account record. Do not include sensitive personal information or another person's private information in it. The instructions prohibit inferring sensitive traits, beliefs or identity. Outputs can be inaccurate, and you can review or change your preferences. We request that the response not be stored as an API response record; that setting is not a promise that the provider retains no security or abuse-prevention records.
AI-assisted research may also help staff propose corrections to public professional profiles using relevant public information and sources. Staff review proposals before applying them. Ordinary searches do not require sending each search to an AI model. This Policy does not grant permission to use private customer information to train general-purpose AI models.
You can disable personalisation or reset interests through the available settings. Disabling stops recording recommendation activity and removes the recorded signals. Reset removes supplied interests and learned activity. Saved events and explicit follows are separate and remain until you remove them or delete the account. Purchases still have to be retained and used for fulfilling orders, accounting and disputes even when they no longer contribute to recommendations.
Automation also supports reservation expiry, ticket validity checks, capacity decisions, fraud controls and payment-provider decisions. It may reject a booking, challenge access or delay a payment where its criteria indicate an issue. Relevant factors include whether the ticket is valid or already used, whether capacity or the admission window permits entry, whether credentials are valid and whether transaction or security signals indicate abuse. A financial or admission decision is distinct from a recommendation.
If a decision based solely on automated personal-data processing has a legal or similarly significant effect on you, you may ask us at contact@fuzer.co for information, meaningful human intervention, an opportunity to put your position and a review, as applicable law provides. We apply the legal conditions and safeguards for such decisions, including stricter rules for special-category data. A provider acting as its own controller may also need to review its own decision. Necessary anti-fraud confidentiality does not remove your statutory safeguards.
We disclose only information relevant to the recipient's role and a lawful purpose:
Service providers acting on our instructions are subject to processing and security obligations. Some recipients act independently and provide their own privacy notices. We do not offer a customer database for sale. Certain analytics disclosures can nevertheless fall within US legal definitions of a "sale", "sharing" or targeted advertising, even without payment; section 10 explains applicable choices. Permission to attend an event is not consent to unrestricted disclosure.
The Platform uses cookies and similar browser or device storage for authentication, security, language and display preferences, consent choices, temporary form progress and other requested functions. Some are session-based; others persist for their configured lifetime or until you clear them. Entry Manager also stores authorised operational data on its device. Blocking storage needed for a requested function can prevent that function from working.
Google Analytics, when enabled, uses identifiers and page or interaction information to measure website use. Referral storage can remember the most recent eligible event promotion link for up to 30 days. These purposes must be assessed separately from essential login and security storage. Where consent is required for analytics, attribution, email tracking or another optional technology, it must be obtained before that technology operates. A single acknowledgement of a cookie message or acceptance of the Terms is not consent to all optional technologies.
You can manage browser storage and device permissions in your browser or device settings. Clearing storage alone may not communicate withdrawal to us and can remove a recorded preference. To withdraw consent or request that optional analytics or other processing be stopped, contact contact@fuzer.co; we will provide the appropriate control or assistance. Withdrawal does not affect the lawfulness of processing before it. Where legally required, withdrawal must be as easy as giving consent.
For organisation marketing, use the unsubscribe link in the message or the available email-preference controls. Following and marketing permission are separate choices; unfollowing also revokes that organisation's marketing consent. You may still receive purchase confirmations, event changes, security alerts and other necessary service messages. If an organisation sends mail outside Fuzer, contact it as well about the information it independently controls.
Fuzer is based in the United Kingdom and serves the United Kingdom, Ireland, Germany, France, the United States and Switzerland. Our infrastructure and service providers operate internationally. Information is not guaranteed to stay only in the UK or EEA; cross-border processing can include the United States and the countries where the relevant provider, authorised event organisation or support operation processes it.
For transfers restricted by UK, EU or Swiss law, the appropriate safeguard must be in place. This may be an applicable adequacy decision, the relevant EU, UK or Swiss-US data-protection framework only where the recipient is certified and the transfer is covered, or approved contractual safeguards. These include EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, and appropriate Swiss adaptations, with required assessments and supplementary protections. A contractual clause cannot make an otherwise unlawful transfer lawful on its own.
You can request details of the destination countries, recipient arrangements and a copy or description of relevant safeguards at contact@fuzer.co. We may redact confidential commercial material without preventing you from understanding the protection. Booking with an overseas event organisation may involve a necessary disclosure to that organisation, which must also handle the information lawfully.
We keep identifiable information only for as long as needed for its specified purpose and legal requirements. The periods differ by record:
There is no general permission to keep everything forever. Where a single fixed period is not appropriate, we use the purpose, sensitivity, minimum legal period, unresolved obligations and realistic need for evidence to set and review retention. Backups and cached copies can take time to expire; they must remain protected and not be reused for unrelated purposes. Data that only has its name removed may still be identifiable and remains subject to this Policy.
We use measures appropriate to the risk, including access controls, secure transmission, limited staff access and operational security processes. No system can be guaranteed completely secure. Organisers are responsible for the devices, exports, credentials and copies they control. Notify us promptly if you suspect a data or account-security incident. We assess incidents and notify affected people and authorities where legally required.
You may object at any time to direct marketing, including related profiling. We will stop that use. You may also object, on grounds relating to your situation, to processing based on legitimate interests. We will stop unless we demonstrate the grounds the law requires to continue, such as overriding legitimate grounds or establishing, exercising or defending legal claims.
Depending on the law and circumstances, you may also request:
Use account controls where available or contact contact@fuzer.co. We may ask for proportionate identity verification and, where necessary, clarification or evidence of authority for someone acting for you. We do not require new information beyond what is reasonably needed to protect your data and handle the request. Rights are subject to legal conditions, other people's rights and applicable exemptions; we will explain a refusal or restriction unless legally prevented.
For UK and EU rights requests, we normally respond without undue delay and within one calendar month. Where law permits more time for a complex or multiple request, we explain the extension within the initial period. Information is normally free; any charge or refusal must meet the applicable legal test. Other jurisdictions' deadlines apply where required. If the relevant record is controlled by an organiser, we can help identify the appropriate contact and forward a request where suitable.
Privacy complaints: contact us by email or post using section 1. For complaints subject to UK data-protection law, we acknowledge within 30 days, investigate without undue delay, keep you informed and communicate the outcome. A complaint does not postpone a separate rights-request deadline.
You may also complain to the UK Information Commissioner's Office, telephone 0303 123 1113, or the competent authority where you live, work or believe an infringement occurred. For Ireland this is the Data Protection Commission; for France, CNIL; for Germany, the competent federal or state supervisory authority listed by the BfDI; and for Switzerland, the Federal Data Protection and Information Commissioner. Contacting us does not waive a right to complain to an authority or seek a judicial remedy.
Where an applicable state privacy law covers Fuzer and your information, you may have rights to know or access the information we process, correct it, delete it, obtain a portable copy, opt out of sale or sharing, targeted advertising and certain consequential profiling, and appeal a refused request. California residents may also have rights to information about disclosures and to limit certain uses of sensitive personal information. We will not unlawfully discriminate against you for exercising a right.
The categories collected and disclosed are described in sections 2 and 5: identifiers and contact information, personal and business characteristics, commercial and financial records, internet or network activity, location, correspondence and content, professional information and preference inferences. They are used for the purposes in sections 3 and 4 and retained according to section 8. Depending on the definition in your state, precise location, account-access information and some information voluntarily provided can be sensitive. We use such information only where necessary for the requested service, security, legal obligations or another permitted purpose, and obtain consent where required. We do not infer sensitive characteristics for personalised advertising.
We do not sell customer lists for money. However, disclosures of online identifiers and browsing activity to an analytics provider may constitute a sale, sharing or targeted advertising under a state's definitions and the provider's arrangements. You can request "Do not sell or share my personal information" or opt out of targeted advertising at contact@fuzer.co. Where law requires recognition of a browser-based universal opt-out signal, including Global Privacy Control, that signal must be respected for the relevant processing. We do not treat the older, non-standardised "Do Not Track" browser setting alone as a universal consent or objection instruction.
You or an authorised agent may submit a rights request by email or post. We verify access, correction and deletion requests proportionately; an opt-out must not be made conditional on unnecessary identity verification. Where applicable, we respond within 45 days, explaining a legally permitted extension within that time; shorter opt-out deadlines take priority. If we deny a request, you may reply asking for an appeal and explaining why. We review and respond within the applicable state deadline and explain any available route to your state regulator. California rights and any required additional methods or notices apply where the statutory thresholds and conditions are met.
We do not knowingly sell or share the personal information of children under 16. The minimum account age below does not remove the additional protections that apply to children's personal information.
Fuzer customer accounts and purchases are available from age 13 under our Terms. Users under 18 must have permission from a parent or legal guardian, and an adult must act for them where required by law or a payment provider. Connect and paid rep work remain restricted to people aged 18 or over. Event admission rules may require a higher age. An adult may supply limited attendee information for a child under 13 where an event permits it, but that child may not open a Fuzer account. The adult and organiser must provide appropriate information to the child or guardian and process only what is necessary. Permission to use Fuzer is not consent to optional marketing, tracking or profiling. Where applicable law requires parental authorisation for processing based on consent, that authorisation is required separately.
Do not put health information, religion, political opinions, sexual orientation, identity documents, financial credentials or other sensitive information in public profiles, ordinary customer notes or interests descriptions. An event choice may itself reveal sensitive information, so access and use must be assessed with that possibility in mind. If sensitive information is necessary for a support request, accessibility arrangement, legal claim or investigation, an appropriate additional legal condition is required, such as explicit consent or necessity for legal claims. Criminal-offence information requires its own legal authority or condition. A general fraud-prevention clause is not a substitute for these requirements.
If you believe someone under 13 has opened an account, a younger user's information is being processed without authorisation required by law, or unnecessary sensitive information has been supplied, contact us. We will assess the facts and take appropriate steps, including restriction or deletion where required.
We may update this Policy to reflect our services, providers, practices or legal requirements. We show the updated date and give additional notice of material changes where required, including before a materially different use of information. We obtain new consent where the law requires it. Continued use does not turn an update into consent or remove rights over information already collected.